CVE-2009-4207: XSS
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4207?
The severity of CVE-2009-4207 is considered high due to the potential for remote attackers to execute arbitrary scripts or HTML.
How do I fix CVE-2009-4207?
To fix CVE-2009-4207, update the Webform module to version 5.x-2.7 or later for Drupal 5.x, or 6.x-2.7 or later for Drupal 6.x.
What versions are affected by CVE-2009-4207?
CVE-2009-4207 affects Webform module versions 5.x before 5.x-2.7 and 6.x before 6.x-2.7.
What is the nature of the vulnerability in CVE-2009-4207?
CVE-2009-4207 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2009-4207 be exploited remotely?
Yes, CVE-2009-4207 can be exploited remotely, allowing attackers to manipulate web submissions.